netlogon: Add necessary security checks for SendToSam
authorGarming Sam <garming@catalyst.net.nz>
Wed, 19 Apr 2017 00:50:55 +0000 (12:50 +1200)
committerAndrew Bartlett <abartlet@samba.org>
Tue, 30 May 2017 06:06:07 +0000 (08:06 +0200)
commitd3e8bcbc9b634c89a98fb63a3b9449d3a628ba39
treebc0c078c076bf21752830e305919cc760369882f
parent452170db2cdc9c7cd474d82e46698ec05fc1c651
netlogon: Add necessary security checks for SendToSam

We eliminate a small race between GUID -> DN and ensure RODC can only
reset bad password count on accounts it is allowed to cache locally.

Signed-off-by: Garming Sam <garming@catalyst.net.nz>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
selftest/knownfail
source4/rpc_server/netlogon/dcerpc_netlogon.c